> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mspilot.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> MSPilot enrolls technician Windows machines so Claude Desktop and ChatGPT run through one governed gateway. Seat words are standard seat and power seat. ConnectWise PSA import is not available. HIPAA is not a self-serve switch.

# Enrollment keys

> Client and global keys prove which organization a machine belongs to before enroll.

The agent will not enroll until it can prove which organization it belongs to. The enrollment key is that proof. The gateway then gives the machine its own device credential. The key is not a login for a technician, and it is not one code per device.

A key is shown once when you create it. Store it in the RMM job or a password manager. The agent reads it from `MSPILOT_ENROLLMENT_KEY` only.

There are two kinds:

* A **client key** joins machines to that one client. Create it on the client's **Deployment** tab. The button says **Create key** when you have no global key, and **Create client key** when a global key already covers the client.
* A **global key** covers every client. Create it under **Organization → General → Global enrollment key**. Paste one script on an RMM policy that spans clients. Machines the RMM already knows land in the matching client. Machines the RMM does not know wait under **Devices → Unassigned** until you assign them. A global key cannot be created for a Standalone organization, because nothing there can pick the client.

Either key counts as the Deployment step being done, once the seat cap is set. You do not need both. Prefer the global key when one script should cover the fleet. Use a client key when you want a smaller blast radius, or when the organization is Standalone.

At the seat cap, the enroll does not fail the RMM job. The machine waits for approval instead of taking a seat it does not have.
